Role Purpose
Lead the design, engineering, and operationalization of enterprise Security Knowledge Graphs that connect security telemetry, assets, identities, vulnerabilities, threats, controls, and incidents into a trusted intelligence layer.
The role is highly hands-on and combines data science, graph engineering, cybersecurity analytics, semantic modeling, and technical leadership to enable attack-path analysis, threat investigation, exposure prioritization, GraphRAG, and AI-assisted security operations.
Key Responsibilities
- Design the Security Knowledge Graph architecture, ontology, taxonomy, entity model, relationship model, provenance model, and lifecycle standards.
- Build production-grade graph ingestion and transformation pipelines for SIEM, EDR/XDR, IAM/PAM, CMDB, vulnerability scanners, cloud security platforms, threat intelligence feeds, security data lakes, and case-management systems.
- Develop entity extraction, identity resolution, deduplication, schema mapping, relationship inference, confidence scoring, temporal modeling, and graph enrichment capabilities.
- Model assets, applications, users, service accounts, privileges, vulnerabilities, misconfigurations, controls, alerts, incidents, indicators, threat actors, campaigns, tactics, techniques, and procedures.
- Implement graph analytics for attack paths, blast radius, privilege escalation, lateral movement, toxic combinations, identity exposure, control gaps, and vulnerability prioritization.
- Build and evaluate graph algorithms and ML models including centrality, community detection, similarity, anomaly detection, node classification, link prediction, embeddings, and Graph Neural Networks.
- Design GraphRAG and knowledge-grounded security assistants that combine graph traversal, vector retrieval, structured evidence, LLM reasoning, citations, and human approval controls.
- Partner with SOC, threat intelligence, IAM, vulnerability management, cloud security, architecture, data engineering, and product teams to convert operational problems into reusable graph-powered capabilities.
- Own technical design reviews, coding standards, model validation, observability, performance tuning, security controls, documentation, and production-readiness gates.
- Mentor data scientists and engineers while remaining accountable for prototypes, reference implementations, critical code, troubleshooting, and complex customer or stakeholder demonstrations.
Mandatory Hands-on Technical Skills
- Knowledge graphs: Ontology and semantic model design; property graphs and RDF; graph schema evolution; knowledge representation; provenance; graph quality; entity and relationship resolution.
- Graph platforms: Deep implementation experience with Neo4j and Cypher; working knowledge of at least one additional platform such as Amazon Neptune, TigerGraph, Azure Cosmos DB Gremlin, ArangoDB, or JanusGraph.
- Graph data science: Neo4j Graph Data Science, NetworkX, PyTorch Geometric or DGL; graph embeddings, pathfinding, similarity, clustering, link prediction, node classification, anomaly detection, and GNN development.
- Programming and engineering: Advanced Python and SQL; APIs; test automation; data structures; distributed processing; Git; CI/CD; containers; infrastructure awareness; production debugging and performance optimization.
- Data engineering: Spark or Databricks, Kafka or equivalent streaming, ETL/ELT, batch and real-time pipelines, data contracts, lineage, cataloguing, quality rules, and scalable cloud storage.
- Cybersecurity: SOC workflows, threat hunting, incident response, detection engineering, vulnerability and exposure management, IAM/PAM, Zero Trust, cloud security, and security control mapping.
- Security standards: Practical use of MITRE ATT&CK, STIX/TAXII, CVE, CWE, CAPEC, NIST frameworks, CIS Controls, and common threat-intelligence vocabularies.
- GenAI and GraphRAG: LLM-based extraction, retrieval orchestration, agent/tool integration, prompt design, evaluation, grounding, guardrails, explainability, and evidence traceability.
- MLOps and observability: Experiment tracking, model versioning, deployment, monitoring, drift and quality checks, auditability, access controls, secrets management, and cost/performance management.
Security Knowledge Graph Engineering Expectations
- Create canonical entity and relationship definitions with stable identifiers, temporal context, source lineage, evidence attributes, confidence scores, and access-control classifications.
- Develop reusable connectors and parsers for structured, semi-structured, and unstructured security sources; implement incremental loading, event-time handling, reconciliation, and recovery patterns.
- Engineer mappings between enterprise security data and standards such as MITRE ATT&CK and STIX while managing versioning, extensions, and organization-specific concepts.
- Design query patterns, graph projections, indexes, constraints, partitioning strategies, retention policies, and caching approaches for high-volume investigative workloads.
- Establish graph quality metrics covering completeness, consistency, freshness, uniqueness, referential integrity, semantic accuracy, and unexplained relationship growth.
- Implement privacy, least-privilege access, tenant or business-unit segregation, audit logging, encryption, secure development, and responsible AI controls.
Illustrative Use Cases
- Attack-path discovery from internet-facing assets to critical applications or privileged identities.
- Identity and privilege-risk analysis across users, service accounts, roles, entitlements, devices, applications, and cloud resources.
- Threat-intelligence fusion linking indicators, malware, campaigns, threat actors, observed telemetry, vulnerabilities, and affected assets.
- Incident investigation timelines, alert correlation, root-cause analysis, blast-radius assessment, and recommended containment evidence.
- Risk-based vulnerability prioritization using exploit context, asset criticality, exposure, compensating controls, active threats, and graph proximity.
- Graph-grounded security copilots for natural-language investigation, explainable recommendations, detection engineering, and analyst productivity.
Leadership & Stakeholder Responsibilities
- Define the technical roadmap, reference architecture, reusable accelerators, engineering backlog, and adoption plan for the Security Knowledge Graph capability.
- Facilitate architecture workshops and communicate trade-offs, risks, dependencies, and business value to security leaders, architects, product owners, and engineering teams.
- Lead design and code reviews; coach teams on graph modeling, data science rigor, cybersecurity context, and reliable AI engineering.
- Coordinate with governance, privacy, legal, risk, and Responsible AI stakeholders to ensure transparent, accountable, and human-supervised use of AI.
- Support solution estimation, delivery planning, technical proposals, demonstrations, and executive-level presentations.
Required Qualifications
- Bachelor’s or Master’s degree in Computer Science, Data Science, Artificial Intelligence, Cybersecurity, Engineering, or a related discipline.
- Demonstrated ownership of at least one production knowledge graph or graph analytics solution, preferably in cybersecurity.
- Strong portfolio of hands-on Python and graph-query development, data pipeline engineering, testing, and production deployment.
- Ability to translate complex security problems into data models, algorithms, measurable experiments, scalable services, and clear technical documentation.
- Excellent communication, mentoring, problem-solving, and cross-functional leadership capabilities.
Preferred Qualifications
- Experience with cloud-native security and data services on Azure, AWS, or Google Cloud; enterprise graph platforms; modern lakehouse architectures; and security copilots or agentic AI patterns.
- Relevant certifications such as CISSP, CISM, GIAC, cloud security, cloud AI/data, or Neo4j Graph Data Science are advantageous but not mandatory.
Key Deliverables and Success Measures
- Approved Security Knowledge Graph architecture, ontology, governance model, and phased implementation roadmap.
- Production-grade ingestion, entity-resolution, enrichment, graph analytics, API, and GraphRAG components with automated tests and operational documentation.
- Measurable improvement in investigation speed, attack-path visibility, correlation quality, vulnerability prioritization, analyst productivity, and explainability.
- Reliable service performance demonstrated through data-quality thresholds, query latency and scale targets, monitoring, security reviews, adoption, and stakeholder acceptance.
- Sustainable engineering capability through reusable assets, standards, knowledge transfer, mentoring, and a prioritized innovation backlog.
Ideal Candidate Profile
A credible technical leader who can move seamlessly from a CISO-level discussion to ontology design, Python development, Cypher optimization, graph algorithm selection, model evaluation, and production troubleshooting.
The successful candidate combines cybersecurity depth with strong data-science discipline and builds trustworthy graph-powered solutions that improve real security decisions, not just demonstrations.